CSIDB logo
Incident

Ayuntamiento de Durango

Incident posture

Attack window
Jan 2023
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Ayuntamiento de Durango
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack of unknown origin targeted the Durango City Council, disrupting municipal operations. The incident occurred on a Sunday morning, prompting immediate reporting to national authorities and cybersecurity experts. Technical teams are assessing impacts on system integrity and security, while critical services like the Citizen Service Center experienced significant operational limitations. Recovery efforts are ongoing to restore normal functionality across affected departments.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 8, 2023, the Durango City Council experienced a cyberattack of unknown origin that disrupted municipal operations. The incident was detected on Sunday morning, prompting immediate notification to Spanish authorities, including the National Cryptological Center (CNN). Municipal IT personnel initiated an impact assessment alongside cybersecurity experts, focusing on evaluating compromises to system integrity and security. The attack significantly impaired the Citizen Service Center (SAC), a primary interface for public inquiries and administrative functions. Other unspecified municipal services also sustained operational damage, though the council did not disclose technical details regarding intrusion methods or data compromise. No threat actor claimed responsibility during the initial response phase.

Response efforts prioritized diagnosing the attack’s scope while maintaining limited public service functionality. The council issued public advisories acknowledging that SAC operations and related services might experience prolonged limitations or procedural changes during recovery. No restoration timeline or specific containment measures were disclosed. Municipal teams continued collaborating with external cybersecurity specialists to restore systems, but the article did not confirm whether critical infrastructure or data repositories were exfiltrated or encrypted. Service disruptions persisted at the time of reporting, with no additional updates on forensic findings or attacker attribution.

Sources

Sources available to members: 1 source.

CSIDB